diff options
| author | Enji Cooper <ngie@FreeBSD.org> | 2026-01-29 01:27:53 +0000 |
|---|---|---|
| committer | Enji Cooper <ngie@FreeBSD.org> | 2026-01-29 01:27:53 +0000 |
| commit | 808413da28df9fb93e1f304e6016b15e660f54c8 (patch) | |
| tree | f3ecb4f928716223c9563ee34e044ab84549debb /test/cmp_client_test.c | |
| parent | 8e12a5c4eb3507846b507d0afe87d115af41df40 (diff) | |
openssl: import 3.5.5vendor/openssl/3.5.5
This change adds OpenSSL 3.5.5 from upstream [1].
The 3.5.5 artifact was been verified via PGP key [2] and by SHA256 checksum [3].
This is a security release, but also contains several bugfixes.
More information about the release (from a high level) can be found in
the release notes [4].
1. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.5/NEWS.md
Diffstat (limited to 'test/cmp_client_test.c')
| -rw-r--r-- | test/cmp_client_test.c | 136 |
1 files changed, 67 insertions, 69 deletions
diff --git a/test/cmp_client_test.c b/test/cmp_client_test.c index 405249010c0b..b0681e85876c 100644 --- a/test/cmp_client_test.c +++ b/test/cmp_client_test.c @@ -61,30 +61,29 @@ static CMP_SES_TEST_FIXTURE *set_up(const char *const test_case_name) return NULL; fixture->test_case_name = test_case_name; if (!TEST_ptr(fixture->srv_ctx = ossl_cmp_mock_srv_new(libctx, NULL)) - || !OSSL_CMP_SRV_CTX_set_accept_unprotected(fixture->srv_ctx, 1) - || !ossl_cmp_mock_srv_set1_refCert(fixture->srv_ctx, client_cert) - || !ossl_cmp_mock_srv_set1_certOut(fixture->srv_ctx, client_cert) - || (srv_cmp_ctx = - OSSL_CMP_SRV_CTX_get0_cmp_ctx(fixture->srv_ctx)) == NULL - || !OSSL_CMP_CTX_set1_cert(srv_cmp_ctx, server_cert) - || !OSSL_CMP_CTX_set1_pkey(srv_cmp_ctx, server_key)) + || !OSSL_CMP_SRV_CTX_set_accept_unprotected(fixture->srv_ctx, 1) + || !ossl_cmp_mock_srv_set1_refCert(fixture->srv_ctx, client_cert) + || !ossl_cmp_mock_srv_set1_certOut(fixture->srv_ctx, client_cert) + || (srv_cmp_ctx = OSSL_CMP_SRV_CTX_get0_cmp_ctx(fixture->srv_ctx)) == NULL + || !OSSL_CMP_CTX_set1_cert(srv_cmp_ctx, server_cert) + || !OSSL_CMP_CTX_set1_pkey(srv_cmp_ctx, server_key)) goto err; if (!TEST_ptr(fixture->cmp_ctx = ctx = OSSL_CMP_CTX_new(libctx, NULL)) - || !OSSL_CMP_CTX_set_log_cb(fixture->cmp_ctx, print_to_bio_out) - || !OSSL_CMP_CTX_set_transfer_cb(ctx, OSSL_CMP_CTX_server_perform) - || !OSSL_CMP_CTX_set_transfer_cb_arg(ctx, fixture->srv_ctx) - || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_SEND, 1) - || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_ERRORS, 1) - || !OSSL_CMP_CTX_set1_oldCert(ctx, client_cert) - || !OSSL_CMP_CTX_set1_pkey(ctx, client_key) - /* client_key is by default used also for newPkey */ - || !OSSL_CMP_CTX_set1_srvCert(ctx, server_cert) - || !OSSL_CMP_CTX_set1_referenceValue(ctx, ref, sizeof(ref))) + || !OSSL_CMP_CTX_set_log_cb(fixture->cmp_ctx, print_to_bio_out) + || !OSSL_CMP_CTX_set_transfer_cb(ctx, OSSL_CMP_CTX_server_perform) + || !OSSL_CMP_CTX_set_transfer_cb_arg(ctx, fixture->srv_ctx) + || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_SEND, 1) + || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_ERRORS, 1) + || !OSSL_CMP_CTX_set1_oldCert(ctx, client_cert) + || !OSSL_CMP_CTX_set1_pkey(ctx, client_key) + /* client_key is by default used also for newPkey */ + || !OSSL_CMP_CTX_set1_srvCert(ctx, server_cert) + || !OSSL_CMP_CTX_set1_referenceValue(ctx, ref, sizeof(ref))) goto err; fixture->req_type = -1; return fixture; - err: +err: tear_down(fixture); return NULL; } @@ -92,9 +91,9 @@ static CMP_SES_TEST_FIXTURE *set_up(const char *const test_case_name) static int execute_exec_RR_ses_test(CMP_SES_TEST_FIXTURE *fixt) { return TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), - OSSL_CMP_PKISTATUS_unspecified) + OSSL_CMP_PKISTATUS_unspecified) && TEST_int_eq(OSSL_CMP_exec_RR_ses(fixt->cmp_ctx), - fixt->expected == OSSL_CMP_PKISTATUS_accepted) + fixt->expected == OSSL_CMP_PKISTATUS_accepted) && TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), fixt->expected); } @@ -110,8 +109,9 @@ static int execute_exec_GENM_ses_test_single(CMP_SES_TEST_FIXTURE *fixture) sk_OSSL_CMP_ITAV_pop_free(itavs, OSSL_CMP_ITAV_free); return TEST_int_eq(OSSL_CMP_CTX_get_status(ctx), fixture->expected) - && fixture->expected == OSSL_CMP_PKISTATUS_accepted ? - TEST_ptr(itavs) : TEST_ptr_null(itavs); + && fixture->expected == OSSL_CMP_PKISTATUS_accepted + ? TEST_ptr(itavs) + : TEST_ptr_null(itavs); } static int execute_exec_GENM_ses_test(CMP_SES_TEST_FIXTURE *fixture) @@ -130,7 +130,7 @@ static int execute_exec_certrequest_ses_test(CMP_SES_TEST_FIXTURE *fixture) OSSL_CMP_CTX_print_errors(ctx); if (!TEST_int_eq(status, fixture->expected) && !(fixture->expected == OSSL_CMP_PKISTATUS_waiting - && TEST_int_eq(status, OSSL_CMP_PKISTATUS_trans))) + && TEST_int_eq(status, OSSL_CMP_PKISTATUS_trans))) return 0; if (fixture->expected != OSSL_CMP_PKISTATUS_accepted) return TEST_ptr_null(res); @@ -153,7 +153,7 @@ static int test_exec_RR_ses(int request_error) if (request_error) OSSL_CMP_CTX_set1_oldCert(fixture->cmp_ctx, NULL); fixture->expected = request_error ? OSSL_CMP_PKISTATUS_request - : OSSL_CMP_PKISTATUS_accepted; + : OSSL_CMP_PKISTATUS_accepted; EXECUTE_TEST(execute_exec_RR_ses_test, tear_down); return result; } @@ -172,9 +172,9 @@ static int test_exec_RR_ses_receive_error(void) { SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); ossl_cmp_mock_srv_set_statusInfo(fixture->srv_ctx, - OSSL_CMP_PKISTATUS_rejection, - OSSL_CMP_CTX_FAILINFO_signerNotTrusted, - "test string"); + OSSL_CMP_PKISTATUS_rejection, + OSSL_CMP_CTX_FAILINFO_signerNotTrusted, + "test string"); ossl_cmp_mock_srv_set_sendError(fixture->srv_ctx, OSSL_CMP_PKIBODY_RR); fixture->expected = OSSL_CMP_PKISTATUS_rejection; EXECUTE_TEST(execute_exec_RR_ses_test, tear_down); @@ -198,8 +198,8 @@ static int test_exec_IR_ses(void) } static int test_exec_REQ_ses_poll(int req_type, int check_after, - int poll_count, int total_timeout, - int expect) + int poll_count, int total_timeout, + int expect) { SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); fixture->req_type = req_type; @@ -207,7 +207,7 @@ static int test_exec_REQ_ses_poll(int req_type, int check_after, ossl_cmp_mock_srv_set_checkAfterTime(fixture->srv_ctx, check_after); ossl_cmp_mock_srv_set_pollCount(fixture->srv_ctx, poll_count); OSSL_CMP_CTX_set_option(fixture->cmp_ctx, - OSSL_CMP_OPT_TOTAL_TIMEOUT, total_timeout); + OSSL_CMP_OPT_TOTAL_TIMEOUT, total_timeout); if (req_type == OSSL_CMP_PKIBODY_IR) { EXECUTE_TEST(execute_exec_certrequest_ses_test, tear_down); @@ -221,22 +221,22 @@ static int checkAfter = 1; static int test_exec_IR_ses_poll_ok(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter, 2, 0, - OSSL_CMP_PKISTATUS_accepted); + OSSL_CMP_PKISTATUS_accepted); } static int test_exec_IR_ses_poll_no_timeout(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter, - 2 /* pollCount */, - checkAfter + 14, /* usually 4 is sufficient */ - OSSL_CMP_PKISTATUS_accepted); + 2 /* pollCount */, + checkAfter + 14, /* usually 4 is sufficient */ + OSSL_CMP_PKISTATUS_accepted); } static int test_exec_IR_ses_poll_total_timeout(void) { return !test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter + 1, - 3 /* pollCount */, checkAfter + 6, - OSSL_CMP_PKISTATUS_waiting); + 3 /* pollCount */, checkAfter + 6, + OSSL_CMP_PKISTATUS_waiting); } static int test_exec_CR_ses(int implicit_confirm, int granted, int reject) @@ -244,12 +244,12 @@ static int test_exec_CR_ses(int implicit_confirm, int granted, int reject) SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); fixture->req_type = OSSL_CMP_PKIBODY_CR; OSSL_CMP_CTX_set_option(fixture->cmp_ctx, - OSSL_CMP_OPT_IMPLICIT_CONFIRM, implicit_confirm); + OSSL_CMP_OPT_IMPLICIT_CONFIRM, implicit_confirm); OSSL_CMP_SRV_CTX_set_grant_implicit_confirm(fixture->srv_ctx, granted); ossl_cmp_mock_srv_set_sendError(fixture->srv_ctx, - reject ? OSSL_CMP_PKIBODY_CERTCONF : -1); + reject ? OSSL_CMP_PKIBODY_CERTCONF : -1); fixture->expected = reject ? OSSL_CMP_PKISTATUS_rejection - : OSSL_CMP_PKISTATUS_accepted; + : OSSL_CMP_PKISTATUS_accepted; EXECUTE_TEST(execute_exec_certrequest_ses_test, tear_down); return result; } @@ -285,9 +285,9 @@ static int test_exec_KUR_ses(int transfer_error, int pubkey, int raverified) } if (pubkey || raverified) OSSL_CMP_CTX_set_option(fixture->cmp_ctx, OSSL_CMP_OPT_POPO_METHOD, - OSSL_CRMF_POPO_RAVERIFIED); - fixture->expected = transfer_error ? OSSL_CMP_PKISTATUS_trans : - raverified ? OSSL_CMP_PKISTATUS_rejection : OSSL_CMP_PKISTATUS_accepted; + OSSL_CRMF_POPO_RAVERIFIED); + fixture->expected = transfer_error ? OSSL_CMP_PKISTATUS_trans : raverified ? OSSL_CMP_PKISTATUS_rejection + : OSSL_CMP_PKISTATUS_accepted; EXECUTE_TEST(execute_exec_certrequest_ses_test, tear_down); return result; } @@ -322,7 +322,7 @@ static int test_exec_KUR_ses_wrong_pub(void) } static int test_certConf_cb(OSSL_CMP_CTX *ctx, X509 *cert, int fail_info, - const char **txt) + const char **txt) { int *reject = OSSL_CMP_CTX_get_certConf_cb_arg(ctx); @@ -341,7 +341,7 @@ static int test_exec_P10CR_ses(int reject) SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); fixture->req_type = OSSL_CMP_PKIBODY_P10CR; fixture->expected = reject ? OSSL_CMP_PKISTATUS_rejection - : OSSL_CMP_PKISTATUS_accepted; + : OSSL_CMP_PKISTATUS_accepted; ctx = fixture->cmp_ctx; if (!TEST_ptr(csr = load_csr_der(pkcs10_f, libctx)) || !TEST_true(OSSL_CMP_CTX_set1_p10CSR(ctx, csr)) @@ -381,9 +381,9 @@ static int execute_try_certreq_poll_test(CMP_SES_TEST_FIXTURE *fixture) && check_after == CHECK_AFTER && TEST_ptr_eq(OSSL_CMP_CTX_get0_newCert(ctx), NULL) && TEST_int_eq(fixture->expected, - OSSL_CMP_try_certreq(ctx, TYPE, NULL, NULL)) + OSSL_CMP_try_certreq(ctx, TYPE, NULL, NULL)) && TEST_int_eq(0, - X509_cmp(OSSL_CMP_CTX_get0_newCert(ctx), client_cert)); + X509_cmp(OSSL_CMP_CTX_get0_newCert(ctx), client_cert)); } static int test_try_certreq_poll(void) @@ -407,7 +407,7 @@ static int execute_try_certreq_poll_abort_test(CMP_SES_TEST_FIXTURE *fixture) && check_after == CHECK_AFTER && TEST_ptr_eq(OSSL_CMP_CTX_get0_newCert(ctx), NULL) && TEST_int_eq(fixture->expected, - OSSL_CMP_try_certreq(ctx, -1 /* abort */, NULL, NULL)) + OSSL_CMP_try_certreq(ctx, -1 /* abort */, NULL, NULL)) && TEST_ptr_eq(OSSL_CMP_CTX_get0_newCert(fixture->cmp_ctx), NULL); } @@ -422,21 +422,21 @@ static int test_try_certreq_poll_abort(void) static int test_exec_GENM_ses_poll_ok(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_GENM, checkAfter, 2, 0, - OSSL_CMP_PKISTATUS_accepted); + OSSL_CMP_PKISTATUS_accepted); } static int test_exec_GENM_ses_poll_no_timeout(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_GENM, checkAfter, - 1 /* pollCount */, checkAfter + 1, - OSSL_CMP_PKISTATUS_accepted); + 1 /* pollCount */, checkAfter + 1, + OSSL_CMP_PKISTATUS_accepted); } static int test_exec_GENM_ses_poll_total_timeout(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_GENM, checkAfter + 1, - 3 /* pollCount */, checkAfter + 2, - OSSL_CMP_PKISTATUS_waiting); + 3 /* pollCount */, checkAfter + 2, + OSSL_CMP_PKISTATUS_waiting); } static int test_exec_GENM_ses(int transfer_error, int total_timeout, int expect) @@ -471,21 +471,19 @@ static int test_exec_GENM_ses_total_timeout(void) static int execute_exchange_certConf_test(CMP_SES_TEST_FIXTURE *fixture) { - int res = - ossl_cmp_exchange_certConf(fixture->cmp_ctx, OSSL_CMP_CERTREQID, - OSSL_CMP_PKIFAILUREINFO_addInfoNotAvailable, - "abcdefg"); + int res = ossl_cmp_exchange_certConf(fixture->cmp_ctx, OSSL_CMP_CERTREQID, + OSSL_CMP_PKIFAILUREINFO_addInfoNotAvailable, + "abcdefg"); return TEST_int_eq(fixture->expected, res); } static int execute_exchange_error_test(CMP_SES_TEST_FIXTURE *fixture) { - int res = - ossl_cmp_exchange_error(fixture->cmp_ctx, - OSSL_CMP_PKISTATUS_rejection, - 1 << OSSL_CMP_PKIFAILUREINFO_unsupportedVersion, - "foo_status", 999, "foo_details"); + int res = ossl_cmp_exchange_error(fixture->cmp_ctx, + OSSL_CMP_PKISTATUS_rejection, + 1 << OSSL_CMP_PKIFAILUREINFO_unsupportedVersion, + "foo_status", 999, "foo_details"); return TEST_int_eq(fixture->expected, res); } @@ -533,10 +531,10 @@ int setup_tests(void) } if (!TEST_ptr(server_key_f = test_get_argument(0)) - || !TEST_ptr(server_cert_f = test_get_argument(1)) - || !TEST_ptr(client_key_f = test_get_argument(2)) - || !TEST_ptr(client_cert_f = test_get_argument(3)) - || !TEST_ptr(pkcs10_f = test_get_argument(4))) { + || !TEST_ptr(server_cert_f = test_get_argument(1)) + || !TEST_ptr(client_key_f = test_get_argument(2)) + || !TEST_ptr(client_cert_f = test_get_argument(3)) + || !TEST_ptr(pkcs10_f = test_get_argument(4))) { TEST_error("usage: cmp_client_test %s", USAGE); return 0; } @@ -545,10 +543,10 @@ int setup_tests(void) return 0; if (!TEST_ptr(server_key = load_pkey_pem(server_key_f, libctx)) - || !TEST_ptr(server_cert = load_cert_pem(server_cert_f, libctx)) - || !TEST_ptr(client_key = load_pkey_pem(client_key_f, libctx)) - || !TEST_ptr(client_cert = load_cert_pem(client_cert_f, libctx)) - || !TEST_int_eq(1, RAND_bytes_ex(libctx, ref, sizeof(ref), 0))) { + || !TEST_ptr(server_cert = load_cert_pem(server_cert_f, libctx)) + || !TEST_ptr(client_key = load_pkey_pem(client_key_f, libctx)) + || !TEST_ptr(client_cert = load_cert_pem(client_cert_f, libctx)) + || !TEST_int_eq(1, RAND_bytes_ex(libctx, ref, sizeof(ref), 0))) { cleanup_tests(); return 0; } |
